Every figure here was traced back to the report that published it, and every source link goes to the document itself rather than a homepage. We removed more statistics than we kept — the widely repeated ones mostly turned out to have no source behind them. Free to cite; a link back is appreciated.
Last verified: August 2026 · Sources: IBM, Verizon, Sophos, FBI, Microsoft, KnowBe4, Kaspersky, Hiscox, Marsh
Average total cost of a data breach among 602 organizations worldwide that were breached between March 2025 and February 2026 — a record high, up 12% year over year. Covers 16 countries and 17 industries, with breaches of 2,590 to 115,380 records. This is a global average across organizations of all sizes, not a US figure and not a small-business figure.
IBM, Cost of a Data Breach Report 2026 (research conducted by Ponemon Institute) (2026)Average total cost of a breach that began with voice or SMS phishing (vishing or smishing) — the costliest of the eight initial attack vectors IBM measured, and the entry point in 17% of breaches studied. The 2026 report does not report email phishing as a separate vector.
IBM, Cost of a Data Breach Report 2026 (research conducted by Ponemon Institute) (2026)Average cost per compromised record where the stolen data was intellectual property — the costliest category of breached data in the study, ahead of customer PII ($192) and employee PII ($188). IP was stolen or compromised in 32% of the breaches studied.
IBM, Cost of a Data Breach Report 2026 (research conducted by Ponemon Institute) (2026)Average time the 602 studied organizations took to identify and contain a breach — 183 days to identify plus 64 days to contain. Up 2.5% from 241 days the previous year, reversing a five-year decline. This is a mean across all breached organizations studied; breaches found by an organization's own IT or security team averaged 209 days, while those disclosed by a third party took 280.
IBM, Cost of a Data Breach Report 2026 (research conducted by Ponemon Institute) (2026)Organizations that used security AI and automation extensively averaged USD 1.93 million less per data breach than organizations that did not use them. Based on 602 organizations worldwide that experienced a data breach between March 2025 and February 2026.
IBM (research conducted by Ponemon Institute), Cost of a Data Breach Report 2026 (2026)Losses self-reported by victims to the FBI's Internet Crime Complaint Center during calendar year 2025, across 1,008,597 complaints. This is reported losses only, not an estimate of all cybercrime; complaints came from more than 200 countries, of which roughly $1.6B of the total was non-US.
FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report (2025)Of the breaches Verizon analysed, 48% involved a third party — a supplier, vendor, hosting or software provider, or data custodian — up from 30% in the 2025 edition and 15% in 2024.
Verizon Business, 2026 Data Breach Investigations Report (DBIR), 19th edition (2026)Share of data breaches that began with exploitation of a vulnerability, up from 20% the year before. This is the first time in the report's 19 years that vulnerability exploitation has been the leading initial access vector, ahead of credential abuse (13%). Based on Verizon's analysis of more than 22,000 confirmed breaches at organizations in 145 countries, covering incidents from November 2024 to October 2025.
Verizon, 2026 Data Breach Investigations Report (DBIR) (2026)Average (mean) cost of recovering from a ransomware attack, excluding any ransom paid. Reported by 2,158 IT and cybersecurity leaders at organizations of 100 to 5,000 employees across 17 countries whose organization was hit by ransomware in the previous 12 months, surveyed January to March 2026. The median recovery cost was $375,000.
Sophos, The State of Ransomware 2026 (seventh edition) (2026)Share of organizations whose data was encrypted in a ransomware attack that paid a ransom. Base: the 1,214 surveyed organizations that had data encrypted, out of 2,158 ransomware victims of 100 to 5,000 employees across 17 countries, surveyed January to March 2026. Sophos's four-year average for this measure is 50%.
Sophos, The State of Ransomware 2026 (seventh edition) (2026)Of 2,158 organizations with 100 to 5,000 employees that were hit by ransomware in the previous 12 months across 17 countries, 17% took more than a month to fully recover. 83% recovered within one month, 55% within one week, and 16% within a day.
Sophos, The State of Ransomware 2026 (independent survey by Vanson Bourne commissioned by Sophos) (2026)Of US small businesses experienced at least one cyber attack in the past 12 months, in a survey of 1,000 US small businesses. The average number of attack attempts per business was 2.38.
Hiscox, Cyber Readiness Report 2026 (US focus), survey by Wakefield Research (2026)Reduction in the risk of account compromise for Microsoft Entra ID (Azure AD) accounts with MFA enabled, measured across accounts flagged for suspicious activity between April and September 2022. Where credentials had already leaked, the reduction was 98.56%.
Microsoft Research, "How effective is multifactor authentication at deterring cyberattacks?" (May 2023) (2023)Share of employees who fell for a simulated phishing test: 33.2% before any training, 20.1% after 90 days, and 4.2% after 12 months of ongoing training. KnowBe4 measured 42 million simulated tests it ran for 14.8 million users at 64,000 of its own customer organizations. These are simulations, not real attacks, and KnowBe4 sells the training being measured.
KnowBe4, 2026 Phishing by Industry Benchmarking Report (press release, 7 July 2026) (2026)Of breaches analysed by Verizon involved credential abuse — an attacker using stolen or compromised credentials — at some point in the breach, out of 19,905 non-Error, non-Misuse breaches. Credential abuse was the entry point in 13% of breaches.
Verizon, 2026 Data Breach Investigations Report (DBIR) (2026)Of 231 million unique passwords found in dark-web leaks between 2023 and 2026 could be cracked in under a minute, when those passwords were hashed with MD5 and attacked with a single consumer graphics card. This measures passwords that had already leaked, not all passwords in use.
Kaspersky, World Password Day 2026 password-cracking research (Kaspersky Digital Footprint Intelligence) (2026)Global cyber insurance rates fell 4% in Q2 2026, the twelfth consecutive quarter of decline. Marsh measures the rate change its own commercial clients saw at renewal, not total premium spend. US cyber rates fell 2%.
Marsh, Global Insurance Market Index, Q2 2026 (2026)You're free to cite any statistic on this page in your articles, presentations, or reports. If you reference this page, a link to nctriangletech.com/tools/cybersecurity-stats is appreciated but not required. All statistics are sourced from publicly available reports.
Suggested citation:
"Cybersecurity Statistics for Small Business (2026)." Triangle Tech. https://nctriangletech.com/tools/cybersecurity-statsMost small business cyber attacks are preventable with basic protections. We help Triangle businesses set up the right defenses without overcomplicating things.